Evidence Collection
Choose a proportionate collection method, minimise unnecessary change, and preserve enough context for another analyst to understand and verify the evidence.
Follow a defensible workflow
Select each stage to see how collection decisions protect evidence value.
Record the system, owner, time range, investigation question, and actions you are authorised to perform.
Ask: What decision must this evidence support?Choose the collection path
Start with the evidence that best answers your question, not the tool with the longest feature list.
Collect targeted system state and high-value artefacts while the computer is running.
Build your foundation
Learn the decision-making behind each collection route before using the tools.
Choose a tool by collection need
Select the evidence need first. The recommendation points to one practical starting guide.
Collect and process selected forensic artefacts quickly using repeatable targets and modules.
Check collection readiness
Confirm the basics before acquiring evidence from a real or simulated system.